Insecure deserialization in Symfony - CVE-2019-10912
Published: April 18, 2019
Vulnerability details
The disclosed vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insecure call of the unserialize() PHP function in untrusted user-input. A remote attacker can send specially crafted HTTP request to the affected system and delete arbitrary files on the system or display raw data output.
Affected software
TYPO3
symfony (Debian package)
php-symfony
php-symfony3
php-symfony4
Fedora
How to mitigate CVE-2019-10912
symfony (Debian package) - update to 2.8.7+dfsg-1.3+deb9u2
TYPO3 - update to 9.5.8
php-symfony - addressed in versions 2.8.51-1.fc28, 2.8.51-1.fc29, 2.8.51-1.fc30
php-symfony3 - addressed in versions 3.4.26-1.fc28, 3.4.26-1.fc29, 3.4.26-1.fc30
php-symfony4 - addressed in versions 4.1.12-1.fc29, 4.2.7-2.fc30
External References
Related Security Bulletins
- Multiple vulnerabilities in Symfony framework
- Debian update for symfony
- Multiple vulnerabilities in Typo3
- Fedora 30 update for php-symfony
- Fedora 28 update for php-symfony
- Fedora 29 update for php-symfony
- Fedora 29 update for php-symfony3
- Fedora 30 update for php-symfony3
- Fedora 28 update for php-symfony3
- Fedora 30 update for php-symfony4
- Fedora 29 update for php-symfony4